You are not imagining it and you did not do anything wrong. Somebody found a hole in the software your website runs on and let themselves in. Here is how to tell for sure, what happens if you wait, and what it costs to have a senior engineer clean it today for a flat $249.
Clean or your money back. Written. Flat $249, no hourly meter.
You do not need to know what your website is built with. We will tell you in the first 10 minutes.
Last updated · Reviewed by Ali Yasin Jatoi
If you ticked even one of these, send us the address of your website and we will look at it for free within the hour.
It almost never means a person targeted you. It means an automated program tried millions of websites, found that yours was running old software, and slipped a few extra files in. Those files then do one of four jobs: send spam, show hidden pages to Google to sell pills or fake shoes, redirect your visitors to somebody who pays per click, or read the card details your customers type in. Your website keeps working, which is exactly the point. If it broke, you would fix it.
Whatever you can see is the symptom. Behind it there are usually two or three quiet ways back in: an extra admin account with an innocent name, a file that hides itself from the plugin list, a scheduled task that reinstalls everything at three in the morning. This is why so many owners clean a site on Monday and watch it break again on Thursday. A real cleanup closes the way in, not just the mess.
Google will start showing a warning screen to your visitors, and once that happens the phone stops entirely. Your host will move from a warning to switching the account off. Your email starts getting blocked because your domain is on a spam list, which means your invoices stop arriving. And the attacker keeps digging, which turns a four hour job into a two day job. Every one of those costs more than $249.
A written report listing every infected file we found, where it was, and what it did. Confirmation that every hidden account and scheduled task is gone. A request to Google to lift any warning. A clean scan you can forward to your host to get switched back on. And an honest sentence about how they got in, which is usually the part nobody else tells you.
Send us the address. We check it from the outside and tell you what we can already see, at no cost and with no card.
We take a full copy of the whole website first, then remove the visible damage so your customers and Google stop seeing it.
Infected files removed, hidden admin accounts deleted, scheduled tasks cleared, every password rotated, updates applied.
We submit the site to Google for review, hand your host their evidence, and watch the site for 30 days in case anything tries to come back.
No quotes, no discovery calls, no hourly meter. You know the number before we touch anything.
One website, one price. Median clean time about 4 hours from the moment we have access. Written report at the end.
Everything above, plus locked down logins, file monitoring, and 60 days of reinfection cover.
Updates on staging, daily backups, monitoring, and a real engineer on call so this never repeats.
Clean or your money back. Written.
If you want to try first, these three steps are safe and genuinely useful. They also make the job faster if you end up calling us.
Stop and call us if: you are about to delete files, edit code, or restore an old backup over the live site. Restoring a backup usually puts the same hole straight back and loses the orders taken since.
Open your own website on your phone, in a private window, by clicking a Google result rather than typing the address. Then search Google for your domain name with the word site in front of it and look for pages you never wrote. Those two checks catch most infections, because a lot of attacks deliberately hide from the owner and only show themselves to visitors arriving from search.
A flat $249 for a standard single website, including the report, the Google review request and 30 days of watching. Online shops with stolen card details and multi site setups are quoted after a free look, and you always get the number before work starts.
Sometimes, but it is a trap more often than not. The hole that let them in was almost certainly in the backup too, so the site gets reinfected within days, and you lose every order, enquiry and post since the backup date. We use backups as evidence, not as the fix.
Usually yes, and fairly quickly if the fake pages are removed and returned properly rather than just deleted. Damage becomes long term when spam pages sit indexed for weeks or when a Google warning stays live. Speed is the whole game here.
Legally and practically, you are. Your host rents you the space and protects the server, not the software you run on it. That surprises most owners, and it is why we wrote a separate page explaining exactly what your host, your developer and your plugin each do.
In our own fleet work the same three causes come up again and again: an out of date plugin with a public hole, a password reused from somewhere that leaked, and an old admin account belonging to someone who left years ago. We tell you which one it was in the report.
Yes. Most of what we see is WordPress and WooCommerce because most of the web is, but the work is the same on other systems. On hosted platforms such as Shopify, Wix or Squarespace the problem is usually a stolen login or a bad app rather than infected files, and we will tell you honestly if that is what you have.
For 30 days after the cleanup it is our problem and we fix it at no cost. After that, the honest answer is that a website nobody updates will eventually be hacked again, which is what the $99 a month care plan exists to prevent.
Deceptive site ahead and this site may be hacked, explained and appealed.
What the host actually needs before they will switch you back on.
The engineer level version, with named malware types and process.
What to do with the spam pages Google already indexed.